Re: [sidr] GOST & SIDR
[Date Prev][Date Next][Thread Prev][Thread Next][Date Index][Thread Index]
Re: [sidr] GOST & SIDR
On Mon, 20 Apr 2009, Randy Bush wrote:
There may (or will) be communities that WILL NOT sign with (=issue
certificates signed by) algorithm X (=RSA). They might happily sign
with algorithm Y (=GOST).
and there will be communities which run x.25 or decnet. not a problem
to me.
Except that if a significant portion of the world uses an algorithm your
validator code can't handle, then you can't validate routes to that part
of the world.
Which means you could be sending your packets to some destinations down
some dark alley.
I would think that the validation of routes is not only of benefit in
packets reaching you, but in you being more confident that your packets
are going where they are meant to go.
(All of this "you" and "your" is only personification - I could say "one's
packets", but that's just a bit too precious.)
Are you really advocating a system that could not support a change of
algorithm? A new algorithm means a new RPKI-v2? (How is that different
from an RPKI with a new OID in the alg field?)
--Sandy
randy
_______________________________________________
sidr mailing list
sidr at ietf.org
https://www.ietf.org/mailman/listinfo/sidr
Note: Messages sent to this list are the opinions of the senders and do not imply endorsement by the IETF.